# T1596.005 Scan Databases

> As of 2026-10-05, T1596.005 (Scan Databases) appears in 26 tracked threats, first reported 2026-04-15 and most recently 2026-09-11, with linked actors including UNC6240, SNOWLIGHT, ShinyHunters; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 26 (14 critical, 8 high, 2 medium)
- **First seen:** 2026-04-15
- **Last seen:** 2026-09-11
- **Threat actors:** 3
- **Detection rules:** 24 (counts only; Blue tier and above)

## Key facts

- **ID:** T1596.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1596
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1596/005/

## Activity timeline

T1596.005 first appeared in tracked threats on 2026-04-15 and was most recently reported on 2026-09-11. The busiest month was 2026-07 with 11 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1596.005 Scan Databases is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1596 Search Open Technical Databases](https://intel.threadlinqs.com/technique/T1596). Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 14 critical, 8 high, 2 medium.

Threats that use T1596.005 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (18 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (13 threats), [T1588.002 Tool](https://intel.threadlinqs.com/technique/T1588.002) (12 threats), [T1588.006 Vulnerabilities](https://intel.threadlinqs.com/technique/T1588.006) (12 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1596.005; the most frequent are [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (2), [SNOWLIGHT](https://intel.threadlinqs.com/actor/SNOWLIGHT) (1), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1596.005.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 2
- [SNOWLIGHT](https://intel.threadlinqs.com/actor/SNOWLIGHT) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1

## Tracked threats

26 tracked threats use T1596.005.

- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Critical Metabase Zero-Day (CVE-2026-72898): Unauthenticated SQL Injection Grants Admin Access, Exploited in…](https://intel.threadlinqs.com/threat/TL-2026-2025) — critical — 2026-08-15
- [Coldcard Hardware Wallet $111M Bitcoin Theft: Weak RNG Private Key Vulnerability (Yasmarang PRNG Fallback)](https://intel.threadlinqs.com/threat/TL-2026-1992) — critical — 2026-08-12
- [Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1985) — critical — 2026-08-11
- [Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1980) — critical — 2026-08-10
- [Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1835) — critical — 2026-08-03
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03
- [COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1822) — critical — 2026-08-02
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization](https://intel.threadlinqs.com/threat/TL-2026-1701) — high — 2026-07-25
- [Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggering](https://intel.threadlinqs.com/threat/TL-2026-1628) — critical — 2026-07-22
- [Capital One Open-Sources VulnHunter: Agentic, Claude-Opus-4.8-Powered Vulnerability Detection and…](https://intel.threadlinqs.com/threat/TL-2026-1583) — 2026-07-21
- [CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handling](https://intel.threadlinqs.com/threat/TL-2026-1515) — high — 2026-07-19
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day](https://intel.threadlinqs.com/threat/TL-2026-1346) — medium — 2026-07-15
- [WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage…](https://intel.threadlinqs.com/threat/TL-2026-1180) — high — 2026-07-10
- [Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240)](https://intel.threadlinqs.com/threat/TL-2026-1094) — critical — 2026-07-03
- [AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)](https://intel.threadlinqs.com/threat/TL-2026-1076) — high — 2026-07-02
- [Apple 'Hide My Email' Aliases Deanonymizable to Real Email Addresses (Unpatched 1+ Year)](https://intel.threadlinqs.com/threat/TL-2026-1043) — medium — 2026-07-01
- [OpenAI Releases GPT-5.5-Cyber: Defender-Restricted AI for Automated Vulnerability Detection, Exploitability…](https://intel.threadlinqs.com/threat/TL-2026-0909) — 2026-06-23
- [ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+…](https://intel.threadlinqs.com/threat/TL-2026-0779) — critical — 2026-06-11
- [SolarWinds Serv-U DoS (CVE-2026-28318) — Actively Exploited Uncontrolled Resource Consumption via…](https://intel.threadlinqs.com/threat/TL-2026-0717) — high — 2026-06-08
- [Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container…](https://intel.threadlinqs.com/threat/TL-2026-0602) — high — 2026-05-27
- [NGINX Rift — CVE-2026-42945 Heap Buffer Overflow in ngx_http_rewrite_module (CVSS v4 9.2 Critical…](https://intel.threadlinqs.com/threat/TL-2026-0517) — critical — 2026-05-14
- [CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free](https://intel.threadlinqs.com/threat/TL-2026-0365) — critical — 2026-04-15

## Related CVEs

CVEs referenced by the tracked threats that use T1596.005, most frequent first.

- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-67649](https://intel.threadlinqs.com/cve/CVE-2025-67649)
- [CVE-2025-7443](https://intel.threadlinqs.com/cve/CVE-2025-7443)
- [CVE-2026-1969](https://intel.threadlinqs.com/cve/CVE-2026-1969)
- [CVE-2026-27771](https://intel.threadlinqs.com/cve/CVE-2026-27771)
- [CVE-2026-32746](https://intel.threadlinqs.com/cve/CVE-2026-32746)
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824)
- [CVE-2026-35271](https://intel.threadlinqs.com/cve/CVE-2026-35271)
- [CVE-2026-35278](https://intel.threadlinqs.com/cve/CVE-2026-35278)
- [CVE-2026-3844](https://intel.threadlinqs.com/cve/CVE-2026-3844)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-40701](https://intel.threadlinqs.com/cve/CVE-2026-40701)
- [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945)
- [CVE-2026-42946](https://intel.threadlinqs.com/cve/CVE-2026-42946)
- [CVE-2026-48907](https://intel.threadlinqs.com/cve/CVE-2026-48907)
- [CVE-2026-50507](https://intel.threadlinqs.com/cve/CVE-2026-50507)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-6433](https://intel.threadlinqs.com/cve/CVE-2026-6433)
- [CVE-2026-72898](https://intel.threadlinqs.com/cve/CVE-2026-72898)
- [CVE-2026-7482](https://intel.threadlinqs.com/cve/CVE-2026-7482)
- [CVE-2026-85706](https://intel.threadlinqs.com/cve/CVE-2026-85706)
- [CVE-2026-87719](https://intel.threadlinqs.com/cve/CVE-2026-87719)

## Detection coverage

Threadlinqs maintains 24 detection rules mapped to T1596.005 (SPL 9, KQL 7, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

24 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1596 Search Open Technical Databases](https://intel.threadlinqs.com/technique/T1596) — 95 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1596.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
